Aeternum Moves Malware Control Onto Polygon

Unit 42 analyzed Aeternum, a C++ loader that uses public Polygon smart contracts as its command-and-control layer instead of a normal server or domain. The loader makes infected Windows hosts poll public remote procedure call endpoints for instructions stored on-chain, then executes encrypted or plaintext commands. That means the command source is the blockchain itself: there is no single backend to seize, sinkhole, or replace, even though the operator can still update the instructions. For defenders, the control plane now sits in an immutable public ledger, so the lasting problem is not one dead server but a command reservoir that can be reused or repopulated without new infrastructure. If your hunting and disruption model assumes C2 lives on takedownable hosts, this is the blind spot that model leaves behind.

Part of the PlainSec briefing for 2026-08-11

Editions

Sources